THREAT OPS › Threat News › [GHSA] GHSA-2wxc-x7rj-hg8f (high) — asyncssh has SCP Path Traversal to Arbitrary File Write
[GHSA] GHSA-2wxc-x7rj-hg8f (high) — asyncssh has SCP Path Traversal to Arbitrary File Write
GHSA-2wxc-x7rj-hg8f Severity: high CVE: CVE-2026-54591
asyncssh has SCP Path Traversal to Arbitrary File Write
| | | |---|---| | Product | asyncssh (all versions through 2.23.0) | | Related | CVE-2019-6111 (same class in OpenSSH) | | Fix | AsyncSSH 2.23.1 |
A malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing `../` traversal se
Indicators of compromise
- CVE-2026-54591cve
- CVE-2019-6111cve
Original source: https://github.com/advisories/GHSA-2wxc-x7rj-hg8f